An access control method and device, and a storage medium

By establishing and updating trust values ​​between the client and the business server, the problem of legitimate clients executing illegal requests is solved, thus improving the security of network access.

CN118827089BActive Publication Date: 2026-04-21CHINA MOBILE COMM GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM GRP CO LTD
Filing Date
2023-09-14
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing technologies, when a client accesses a business system, a legitimate client may execute an illegal request process, leading to a decrease in network access security.

Method used

On the target access path between the client and the business server, after receiving a business access request, the current trust value is determined based on the access traffic, the initial trust value of the multi-level tags is updated, the updated trust value is obtained, and it is transmitted to the business server to determine the execution process of the access request.

Benefits of technology

By adjusting the trust value, the security of network access is improved, ensuring the execution of legitimate requests and the blocking of illegitimate requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827089B_ABST
    Figure CN118827089B_ABST
Patent Text Reader

Abstract

This application discloses an access control method, apparatus, and storage medium, comprising: upon receiving a business access request transmitted by a client on a target access path between a client and a business server, determining a current trust value based on the access traffic corresponding to the business access request; updating multiple initial trust values ​​corresponding to multi-level tags using the current trust value to obtain multiple updated trust values; transmitting the multiple updated trust values ​​and the business access request to the business server; so that the business server can determine the execution process of the business access request based on the multiple updated trust values.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to an access control method, apparatus, and storage medium. Background Technology

[0002] With the development of network technology, clients can access different business systems to obtain different business information, which improves the convenience of information acquisition.

[0003] In related technologies, when a client accesses a business system, the business system identifies the client's IP address and user information, determines the client's legitimacy based on the IP address and user information, and processes the client's access request if the client is legitimate. However, because a legitimate client may request to perform illegal actions in different scenarios, this reduces the security of network access. Summary of the Invention

[0004] To address the aforementioned technical problems, embodiments of this application aim to provide an access control method, apparatus, and storage medium that can improve the security of network access.

[0005] The technical solution of this application is implemented as follows:

[0006] This application provides an access control method, the access control method comprising:

[0007] When a business access request is received from the client on the target access path between the client and the business server, the current trust value is determined based on the access traffic corresponding to the business access request.

[0008] The current trust value is used to update multiple initial trust values ​​corresponding to multi-level tags, resulting in multiple updated trust values.

[0009] The updated trust values ​​and the service access request are transmitted to the service server so that the service server can determine the execution process of the service access request based on the updated trust values.

[0010] This application provides an access control device, the device comprising:

[0011] The determining unit is used to determine the current trust value based on the access traffic corresponding to the service access request when a service access request transmitted by the client is received on the target access path between the client and the service server.

[0012] The update unit is used to update multiple initial trust values ​​corresponding to multi-level tags using the current trust value, so as to obtain multiple updated trust values;

[0013] A transmission unit is used to transmit the multiple updated trust values ​​and the service access request to the service server, so that the service server can determine the execution process of the service access request based on the multiple updated trust values.

[0014] This application provides an access control device, the device comprising:

[0015] The system includes a memory, a processor, and a communication bus. The memory communicates with the processor via the communication bus. The memory stores an access control program executable by the processor. When the access control program is executed, the access control method described above is performed by the processor.

[0016] This application provides a storage medium storing a computer program for use in an access control device, characterized in that the computer program, when executed by a processor, implements the access control method described above.

[0017] This application provides an access control method, apparatus, and storage medium. The access control method includes: upon receiving a service access request transmitted by a client on a target access path between a client and a service server, determining a current trust value based on the access traffic corresponding to the service access request; updating multiple initial trust values ​​corresponding to multi-level tags using the current trust value to obtain multiple updated trust values; transmitting the multiple updated trust values ​​and the service access request to the service server; and allowing the service server to determine the execution process of the service access request based on the multiple updated trust values. Using the above method, the access control apparatus determines the current trust value based on the access traffic corresponding to the service access request, adjusts multiple initial trust values ​​using the current trust value to obtain multiple updated trust values, and sends the multiple updated trust values ​​and the service access request to the service server. This allows the service server to determine whether to execute the access process corresponding to the service access request based on the multiple updated trust values, improving network access security. Attached Figure Description

[0018] Figure 1 A flowchart of an access control method provided in an embodiment of this application;

[0019] Figure 2 An exemplary access control block diagram provided for embodiments of this application;

[0020] Figure 3 A schematic diagram illustrating an exemplary access control flow interaction process provided in an embodiment of this application;

[0021] Figure 4 A flowchart illustrating an exemplary access control method provided in this application embodiment;

[0022] Figure 5 A schematic diagram of the composition structure of an access control device provided in this application embodiment. Figure 1 ;

[0023] Figure 6 A schematic diagram of the composition structure of an access control device provided in this application embodiment. Figure 2 . Detailed Implementation

[0024] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0025] This application provides an access control method, which is applied to an access control device. Figure 1 A flowchart of an access control method provided in an embodiment of this application is shown below. Figure 1 As shown, access control methods may include:

[0026] S101. On the target access path between the client and the business server, when a business access request is received from the client, the current trust value is determined based on the access traffic corresponding to the business access request.

[0027] The access control method provided in this application embodiment is applicable to scenarios where the client's trust value is adjusted to determine the execution process of a business access request based on the updated trust value.

[0028] In the embodiments of this application, the access control device can be implemented in various forms. For example, the access control device described in this application may include devices such as mobile phones, cameras, tablet computers, laptops, handheld computers, personal digital assistants (PDAs), portable media players (PMPs), navigation devices, wearable devices, smart bracelets, pedometers, etc., as well as devices such as digital TVs, desktop computers, servers, etc.

[0029] In this embodiment, the target access path can be a configured access path between the client and the business server, or an access path between the client and the business server established by the access control method. The specific way the access control device obtains the target access path can be determined according to the actual situation, and this embodiment does not limit it.

[0030] In this embodiment of the application, the business server can be a business server in the financial industry, such as banking, securities, and insurance; it can also be a business server in industries including justice, fire protection, and security; or it can be other business servers. The specific business server can be determined according to the actual situation, and this embodiment of the application does not limit it.

[0031] In this embodiment, the access control device can be a device installed in the business server, that is, the access control device is part of the business server; the access control device can also be a business server equipped with an access control method; the specific relationship between the access control device and the business server can be determined according to the actual situation, and this embodiment does not limit it.

[0032] In this embodiment, the access control device is specifically a meta-trust control device, which includes a full-dimensional and full-volume behavior audit module, a tag classification and grading module, and a carrier network control module.

[0033] It should be noted that the full-dimensional, full-volume behavior audit module is used to verify identity by combining the operator's unique SIM card authentication. After successful user authentication, it uses historical identity authentication information and user behavior history information to train and derive the user's trust value. The tag classification and grading module is used to set three levels of tags based on the business system type: comprehensive tags, industry tags, and domain tags. It calculates the three trust values ​​corresponding to a user's three-level tags. Based on the business attributes of the target platform the customer wants to access, it matches the corresponding three-level tags of the business system and feeds them back to the full-dimensional, full-volume behavior audit module, empowering the business system and enabling collaboration and sharing between different business systems. The operator network control module is used for boundary protection, responsible for blocking access from users whose trust values ​​are below a set threshold, preventing untrusted users from illegally accessing the business system. Application protection is responsible for filtering user access behavior, forwarding legitimate access behavior to the business system, and blocking illegal access behavior.

[0034] In this embodiment of the application, the service access request can be any "ask" request corresponding to any service on the service server.

[0035] In this embodiment of the application, the process by which the access control device determines the current trust value based on the access traffic corresponding to the service access request includes: when the access traffic is traffic without access risk, using a first preset value as the current trust value; and when the access traffic is traffic with access risk, using a second preset value as the current trust value.

[0036] In this embodiment, the first preset value and the second preset value can be values ​​configured in the access control device or values ​​transmitted to the access control device from other devices. The specific way in which the access control device obtains the first preset value and the second preset value can be determined according to the actual situation, and this embodiment does not limit this.

[0037] It should be noted that the first preset value indicates that the access traffic is free of access risk. The second preset value indicates that the access traffic is at risk.

[0038] In this embodiment, the first preset value and the second preset value are different values. For example, the first preset value can be 1 and the second preset value can be 0; the first preset value can also be other values ​​and the second preset value can also be other values. The specific values ​​of the first preset value and the second preset value can be determined according to the actual situation, and this embodiment does not limit them.

[0039] For example, if the access control device detects internet traffic that accesses a known botnet / C&C (Command and Control) network / malicious Uniform Resource Locator (URL), then the access traffic is considered to be at risk of access; if the detected access traffic is internet traffic that does not access a known botnet / C&C network / malicious URL, then the access traffic is considered to be at no risk of access.

[0040] In this embodiment, when the access control device receives a business access request transmitted by the client on the target access path between the client and the business server, before determining the current trust value based on the access traffic corresponding to the business access request, it obtains the login object information of the login object when it receives a login request from the client to log in to the business server; if the login object information is verified successfully, it transmits the login object information to the business server so that the business server can perform object identity authentication based on the login object information; if it receives feedback information from the business server indicating successful object identity authentication, it obtains the business attribute information corresponding to the business server; it determines multiple initial trust values ​​of the login object information based on the business attribute information; and it transmits multiple initial trust values ​​to the business server so that the business server can determine the client's trustworthiness based on the multiple initial trust values; if it receives indication information from the business server that the client is a trusted client, it establishes the target access path from the client to the business server.

[0041] In this embodiment, the login object can be a user. The login object information includes the user's mobile phone number and Subscriber Identity Module (SIM) number.

[0042] In this embodiment of the application, the login request carries login object information.

[0043] In this embodiment, the verification process for login object information can be based on existing technology, and the specific implementation method can be determined according to the actual situation. This embodiment does not limit this. For example: When a user accesses the internet via a mobile operator's data, the Gateway GPRS Support Node (GGSN) of the core network communication element obtains the user's mobile phone number and inserts it into the network data packet of the authentication request. The user initiates a SIM card authentication request to the authentication server. The authentication server calls the operator's communication network element to send an authentication message to the SIM card. After the SIM card parses the message, a pop-up window displays the authentication request on the mobile terminal. After the user confirms that everything is correct, they enter their Personal Identification Number (PIN) to complete the authentication confirmation, thus completing the verification process for the login object information.

[0044] In this embodiment of the application, the process of the business server performing object identity authentication on the login object information can be as follows: the business server confirms whether there is registration information corresponding to the login object information. If there is, the object identity authentication is successful; otherwise, the object identity authentication fails.

[0045] In this embodiment, the process of the access control device transmitting login object information to the business server can be a process of transmitting a login request carrying the login object information to the business server. Upon receiving feedback information from the business server indicating successful object authentication, the access control device determines that the business server has approved the login request.

[0046] In this embodiment, the process of obtaining the business attribute information corresponding to the business server can be as follows: obtaining the business attribute information of the business server from the feedback information (i.e., the feedback information carries the business attribute information); obtaining the business attribute information of the business server from the received interaction information between the business server and the business server before receiving the feedback information of successful object authentication transmitted by the business server; or obtaining the business attribute information corresponding to the business server through other means. The specific method of obtaining the business attribute information corresponding to the business server can be determined according to the actual situation, and this embodiment does not limit it.

[0047] In this embodiment of the application, after transmitting multiple initial trust values ​​to the business server, the business server can determine the trustworthiness of the client based on the multiple initial trust values. If the business server determines that the client is trustworthy based on the multiple initial trust values, it will transmit indication information that the client is a trustworthy client to the access control device.

[0048] In this application embodiment, the method by which the access control device establishes the target access path from the client to the business server can be the existing technology. The specific implementation method can be determined according to the actual situation, and this application embodiment does not limit it.

[0049] For example, the access control device can authorize the user (client) with the permissions assigned by the business system (business server) and open the end-to-end (business server) access path, thus obtaining the target access path.

[0050] In this embodiment of the application, when the access control device receives indication information from the service server that the client is a trusted client, the process of establishing a target access path from the client to the service server further includes: obtaining the client's client permission information from the indication information; and transmitting the target access path and the client permission information to the client so that the client can execute the access process of the service access request according to the client permission information and the target access path.

[0051] In this embodiment of the application, the instruction information carries client permission information.

[0052] In this embodiment of the application, the process by which the access control device determines multiple initial trust values ​​of login object information based on business attribute information includes: determining industry tags and domain tags that match the business attribute information; determining a comprehensive tag corresponding to the login object information; and using the industry tag, domain tag, and comprehensive tag as multi-level tags; and fusing multiple first risk values ​​and multiple second risk values ​​to obtain multiple initial trust values ​​corresponding to the multi-level tags.

[0053] In this embodiment, the process of determining industry tags and domain tags that match the business attribute information can be as follows: inputting the business attribute information into a user profile model to obtain industry tags and domain tags; or searching for a target business attribute that is the same as the business attribute information in a preset correspondence between business attributes and preset tags, and determining the target tag (i.e., industry tag and domain tag) corresponding to the target business attribute in the preset correspondence between business attributes and preset tags, thereby obtaining industry tags and domain tags; or determining industry tags and domain tags that match the business attribute information through other methods; the specific implementation process can be determined according to the actual situation, and this embodiment does not limit it.

[0054] In this embodiment, the tag recognition model can be a model configured in the access control device, or it can be a model obtained by the access control device in other ways. The specific way in which the access control device obtains the tag recognition model can be determined according to the actual situation, and this embodiment does not limit it.

[0055] It should be noted that a label recognition model can be trained using the sample business attributes and the sample labels corresponding to those attributes.

[0056] In this embodiment, the access control device includes a tag classification and grading module. This module is used to set three levels of tags: general, industry, and domain. Based on the business attributes of the target platform the customer wants to access, it matches the tags corresponding to the business systems. Tags are labeled based on the user's historical access information. The business system URL itself represents the user's tag preference weight, and the content corresponding to the business system URL reflects the tag information. In other words, the URL determines the weight, and the content determines the tag.

[0057] In this application embodiment, a three-level tag category (multi-level tag) is set to form a two-dimensional table of full-dimensional and full-volume industry tag set (as shown in Table 1). The comprehensive tag trust value represents the trust value obtained by the user when accessing all types of business systems on the Internet, the industry tag trust value represents the trust value obtained by the user when accessing business systems in industries such as government, finance, and education, and the domain tag trust value represents the trust value obtained by the user when accessing business systems in different domains within a certain industry.

[0058] Table (1)

[0059]

[0060]

[0061] In this embodiment, based on the user's historical access DPI logs obtained from the full-dimensional, full-volume behavior audit module, the data content carried in the network is parsed through traffic identification, including the user's source IP, source port, destination IP, destination port, access URL, and access content. The number of identical URL addresses is counted. If it is an HTTPS protocol, the number of identical source IPs is counted, and DNS domain name resolution is performed on the source IP. The webpage content is obtained based on the URL address or domain name, and the key information of the webpage is extracted. Data labeling is completed according to the label classification in step 1 to form a training dataset. Based on the training data, a user profile model (i.e., label recognition model) based on SVM (Support Vector Machine) is constructed. Real-time access data is used as test data. The real-time access data label is predicted through the user profile model to obtain three-level labeling of the real-time access data (business attribute information is input into the user profile model to obtain industry labels and domain labels). Label empowerment is achieved by sharing the comprehensive label: trust value T1, industry label: trust value T2, and domain label: trust value T3 with all business systems in the form of API interfaces to realize inter-business collaboration.

[0062] In this embodiment, the correspondence between preset service attributes and preset tags can be a correspondence configured in the access control device, a correspondence transmitted from other devices to the access control device, or a correspondence obtained by the access control device through other means. The specific way in which the access control device obtains the correspondence between preset service attributes and preset tags can be determined according to the actual situation, and this embodiment does not limit it.

[0063] In this embodiment, the method for determining the comprehensive tag corresponding to the login object information can be to use the industry tag and domain tag corresponding to the login object information as the comprehensive tag. It should be noted that the comprehensive tag may also include other tag information of the business server, which can be determined according to the actual situation, and this embodiment does not limit this.

[0064] In this embodiment of the application, the method of determining multiple initial trust values ​​based on historical access information can be as follows: determine multiple first risk values ​​and multiple second risk values ​​based on historical access information; and fuse the multiple first risk values ​​and multiple second risk values ​​according to multi-level labels to obtain multiple initial trust values ​​corresponding to multi-level labels.

[0065] S102. Update multiple initial trust values ​​corresponding to multi-level labels using the current trust value to obtain multiple updated trust values.

[0066] In this embodiment of the application, after the access control device determines the current trust value based on the access traffic corresponding to the service access request, it uses the current trust value to update the multiple initial trust values ​​corresponding to the multi-level tags to obtain multiple updated trust values.

[0067] It should be noted that multiple initial trust values ​​are trust values ​​determined during the client's previous business access to the business server, or trust values ​​determined based on the client's and the corresponding customer's historical behavior information.

[0068] In this embodiment of the application, multi-level tags correspond to multiple initial trust values, that is, a first-level tag corresponds to one initial trust value. For example, a third-level tag corresponds to three initial trust values.

[0069] In this embodiment of the application, the multi-level tags include comprehensive industry and domain tags, industry tags, and domain tags. Correspondingly, multiple initial trust values ​​include the comprehensive industry and domain tag value (i.e., the initial trust value of the comprehensive industry and domain tag), the industry tag value (the initial trust value of the industry tag), and the domain tag value (the initial trust value of the domain tag).

[0070] In this embodiment of the application, the process by which the access control device updates multiple initial trust values ​​corresponding to multi-level labels using the current trust value to obtain multiple updated trust values ​​includes: obtaining historical access information corresponding to the login object, and obtaining multiple first historical access traffic corresponding to multi-level labels within a first preset historical time period and multiple first historical access logs corresponding to multi-level labels within a second preset historical time period from the historical access information; determining multiple first risk values ​​based on the multiple first historical access traffic; determining multiple second risk values ​​based on the multiple first historical access logs; and fusing the current trust value, the multiple first risk values, and the multiple second risk values ​​to obtain multiple updated trust values.

[0071] It should be noted that multiple first historical access traffic refers to network traffic that is at risk; multiple first historical access logs refer to all access logs within the second preset time period; and the login object refers to the object that transmits business access requests through the client.

[0072] In this embodiment, the access control device can obtain historical access information corresponding to the logged-in object from the database; or it can obtain historical access information corresponding to the logged-in object from other devices. The specific method by which the access control device obtains historical access information corresponding to the logged-in object can be determined according to the actual situation, and this embodiment does not limit it.

[0073] In this embodiment, the first preset historical time period can be a time period configured in the access control device; or it can be a time period obtained by the access control device in other ways. The specific way in which the access control device obtains the first preset historical time period can be determined according to the actual situation, and this embodiment does not limit it.

[0074] It should be noted that the first preset historical event period can be three months, six months, or 100 days. The specific duration of the first preset historical event period can be determined according to the actual situation, and this application embodiment does not limit it.

[0075] In this embodiment, the second preset historical time period can be a time period configured in the access control device; or it can be a time period obtained by the access control device in other ways. The specific way in which the access control device obtains the second preset historical time period can be determined according to the actual situation, and this embodiment does not limit it.

[0076] In this embodiment, the first preset historical time period may be different from the second preset historical time period, or the first preset historical time period may be the same as the second preset historical time period. The specific time period can be determined according to the actual situation, and this embodiment does not limit it.

[0077] It should be noted that the second preset historical time period can be one year, three years, or 1000 days. The specific duration of the second preset historical time period can be determined according to the actual situation, and this application embodiment does not limit it.

[0078] In this embodiment, the multi-level labels correspond one-to-one with multiple first historical access traffic, that is, one level label corresponds to one first historical access traffic. Similarly, the multi-level labels correspond one-to-one with multiple first historical access logs, that is, one level label corresponds to one first historical access log.

[0079] In this embodiment of the application, the process by which the access control device determines multiple first risk values ​​based on multiple first historical access traffic includes: obtaining multiple first access traffic traced back based on the login object and multiple second access traffic traced back based on the client's address information from the multiple first historical access traffic; determining multiple third risk values ​​based on the multiple first access traffic and multiple first attenuation coefficients; determining multiple fourth risk values ​​based on the multiple second access traffic and multiple first attenuation coefficients; and fusing the multiple third risk values ​​and multiple fourth risk values ​​to obtain multiple first risk values.

[0080] It should be noted that the multiple second access traffic refers to the access traffic other than the multiple first access traffic among the multiple first historical access traffic.

[0081] In the embodiments of this application, the multiple first attenuation coefficients can be attenuation coefficients configured in the access control device; they can also be attenuation coefficients transmitted from other devices to the access control device; or they can be attenuation coefficients obtained by the access control device in other ways; the specific way in which the access control device obtains the multiple first attenuation coefficients can be determined according to the actual situation, and the embodiments of this application do not limit this.

[0082] In the embodiments of this application, the multi-level labels correspond one-to-one with multiple first attenuation coefficients, that is, one level label corresponds to one first attenuation coefficient.

[0083] In this embodiment of the application, the process of determining multiple third risk values ​​based on multiple first access traffic and multiple first attenuation coefficients can be as follows: First, filter out access traffic corresponding to multi-level tags from multiple first access traffic (i.e., group multiple first access traffic according to multi-level tags) to obtain multiple groups of first access traffic; match multiple groups of first access traffic with multiple first attenuation coefficients to obtain each first attenuation coefficient corresponding to each group of first access traffic; obtain each third risk value based on each group of first access traffic and each first attenuation coefficient; and obtain multiple third risk values ​​based on each third risk value (multiple third risk values ​​include each third risk value).

[0084] It should be noted that the process of obtaining multiple third risk values ​​based on each group of first access traffic and each first attenuation coefficient can be summarized as follows: First, determine each group of access risk coefficients based on each group of first access traffic; second, determine the product between each group of access risk coefficients and the first attenuation coefficient in each group of first attenuation coefficients to obtain the first group of first products; third, determine the sum of the first group of first products to obtain the first third risk value; fourth, determine the product between each group of access risk coefficients and the second attenuation coefficient in each group of first attenuation coefficients to obtain the second group of first products; fifth, determine the sum of the second group of first products to obtain the second third risk value; and so on; sixth, determine the product between each group of access risk coefficients and the last attenuation coefficient in each group of first attenuation coefficients to obtain the last group of first products; seventh, determine the sum of the last group of first products to obtain the last third risk value; and finally, use the first third risk value, the second third risk value, ..., the last third risk value as multiple third risk values.

[0085] In this embodiment of the application, the process of determining multiple fourth risk values ​​based on multiple second access traffic and multiple first attenuation coefficients can be as follows: First, filter the access traffic corresponding to the multi-level labels from the multiple second access traffic (i.e., group the multiple second access traffic according to the multi-level labels) to obtain multiple groups of second access traffic; second, match the multiple groups of second access traffic with the multiple first attenuation coefficients to obtain each first attenuation coefficient corresponding to each group of second access traffic; third, obtain each fourth risk value based on each group of second access traffic and each first attenuation coefficient; and finally, obtain multiple fourth risk values ​​based on each fourth risk value (multiple fourth risk values ​​include each fourth risk value).

[0086] It should be noted that the process of obtaining multiple fourth risk values ​​based on each group of second access traffic and each first attenuation coefficient can be as follows: First, determine each group of access risk parameters based on each group of second access traffic; second, determine the product between the first access risk parameter in each group of access risk parameters and the first attenuation coefficient in each first attenuation coefficient to obtain the first group of second products; third, determine the sum of the first group of second products to obtain the first fourth risk value; fourth, determine the product between the second access risk parameter in each group of access risk parameters and the second attenuation coefficient in each first attenuation coefficient to obtain the second group of second products; fifth, determine the sum of the second group of second products to obtain the second fourth risk value; and so on; sixth, determine the product between the last access risk parameter in each group of access risk parameters and the last attenuation coefficient in each first attenuation coefficient to obtain the last group of second products; sixth, determine the sum of the last group of second products to obtain the last fourth risk value; and finally, use the first fourth risk value, the second fourth risk value, ..., the last fourth risk value as multiple fourth risk values.

[0087] In this embodiment of the application, the process of fusing multiple third risk values ​​and multiple fourth risk values ​​to obtain multiple first risk values ​​can be as follows: obtaining multiple sets of first fusion coefficients corresponding to multi-level labels; determining multiple third trust values ​​based on preset parameters and multiple third risk values; determining multiple fourth trust values ​​based on preset parameters and multiple fourth risk values; and fusing the multiple third trust values ​​and multiple fourth trust values ​​using the multiple sets of first fusion coefficients to obtain multiple first risk values.

[0088] It should be noted that the preset parameter can be 1, or it can be other parameters; the specific preset parameter can be determined according to the actual situation, and this application embodiment does not limit it.

[0089] In this embodiment, the multiple sets of first fusion coefficients can be parameters configured in the access control device; they can also be parameters transmitted to the access control device from other devices; or they can be parameters obtained by the access control device in other ways. The specific way in which the access control device obtains the multiple sets of first fusion coefficients can be determined according to the actual situation, and this embodiment does not limit this.

[0090] It should be noted that multiple sets of first fusion coefficients correspond one-to-one with multiple level labels, that is, one set of first fusion coefficients corresponds to one level label.

[0091] For example, the access control device includes a full-dimensional, full-volume behavior auditing module. After obtaining a user's mobile phone number, this module analyzes the number's historical behavior. By monitoring mobile internet traffic accessing known botnets / C&C networks / malicious URLs, it traces the traffic back to the mobile phone number, thereby determining the risk level of the mobile terminal associated with that number. Similarly, by obtaining the user's IP address from the user authentication request packet, and analyzing the IP address's historical behavior, the module monitors internet traffic accessing known botnets / C&C networks / malicious URLs within the operator's IP metropolitan area network, thereby determining the IP address's risk level.

[0092] First, the access control device acquires the daily risk coefficient (access risk coefficient corresponding to the first access traffic) R, R ∈ [0,100] for the mobile phone number within a certain set time period (i.e., the first preset historical time period), n, where n ∈ [0,100]; and the daily risk coefficient (access risk parameter corresponding to the second access traffic) Q, where Q ∈ [0,1]. Since the acquired data is not parsed, an attenuation factor is set. Because it is historical access data, the data's timeliness decreases with time; therefore, time is defined as the attenuation factor (first attenuation coefficient) α, where α ∈ (0,1) is calculated by decreasing the attenuation value by 0.01 for each additional day. Then, a historical risk assessment is performed (i.e., determining the third risk value). i∈[1,n], obtain the trust value (third trust value) T. 手机号码 =1-S 手机号码 Conduct a historical risk assessment (i.e., determine the fourth risk value). i∈[1,n], obtain the trust value (fourth trust value) T. IP地址 =1-S IP地址 Finally, the weights λ1 for the trust value of the mobile phone number and λ2 for the trust value of the IP address are set, thus determining the first fusion coefficients (λ1 and λ2), where λ1∈[0,1], λ2∈[0,1], and λ1+λ2=1; based on the third trust value, the fourth trust value, and the first fusion coefficient, an overall trust value assessment is performed (to determine the first risk value), T 通信网络 =λ1T 手机号码+λ2T IP地址 , T∈[0,1].

[0093] It should be noted that the full-dimensional, full-volume behavior auditing module is used to perform identity authentication and network access behavior auditing processes. Specifically, during identity authentication, it receives users' business access requests and collaborates with the business platform to authenticate the identity information (phone number, SIM card) submitted by the user. On the one hand, it verifies the user's true identity, enabling access for legitimate users and blocking unauthorized users; on the other hand, after verifying the user's number information, it assigns an initial trust value to the number based on operator communication network monitoring data.

[0094] In this embodiment of the application, the process of determining multiple second risk values ​​by the access control device based on multiple first historical access logs includes: obtaining access logs without access risk from each of the multiple first historical access logs to obtain multiple first access logs; and determining multiple second risk values ​​based on the multiple first access logs, the multiple first historical access logs, and a first attenuation coefficient.

[0095] In this embodiment of the application, the method for determining multiple second risk values ​​based on multiple first access logs, multiple first historical access logs, and a first attenuation coefficient includes: firstly, grouping multiple first historical access logs according to multi-level labels to obtain a set of first historical access logs corresponding to each level label; dividing the set of first historical access logs according to the log generation time to obtain the first historical access logs corresponding to each day within a second preset historical time period; grouping multiple first access logs according to multi-level labels to obtain a set of first access logs corresponding to each level label; dividing the set of first access logs according to the log generation time to obtain the first access logs corresponding to each day within the second preset historical time period; sequentially dividing the data packet volume of the first access logs corresponding to each day by the first historical access logs corresponding to each day and multiplying by the first attenuation coefficient to obtain the risk value of each day corresponding to each level label; accumulating the risk values ​​of each day to obtain a second risk value corresponding to that level label; and determining multiple second risk values ​​corresponding to multiple level labels in the manner of determining a second risk value under a level label.

[0096] In this embodiment, the full-dimensional, full-volume behavior auditing module is also used to acquire data traffic within a set time period (second preset historical time period) n, n∈[0,1000], and to complete user access log filtering based on DPI parsing data and the identity information of the accessing user, thereby completing the collection of the user's historical access data. The acquired data packets are parsed using DPI, and their traffic characteristics are compared with the characteristics of existing database records to mark normal data packets. The total number of data packets S = (S1, S2, ... S...) is calculated daily.n ) and the number of packets with normal behavior P = (P1, P2, ... P n A decay factor is set. Since this is historical access data, the timeliness of the data decreases with time. Therefore, time is defined as the decay factor (first decay coefficient) α, where α∈(0,1). The decay value decreases by 0.001 for each additional day. Historical behavior trust value assessment. i∈[1,n].

[0097] In this embodiment of the application, the process by which the access control device fuses the current trust value, multiple first risk values, and multiple second risk values ​​to obtain multiple updated trust values ​​includes: fusing the current trust value with multiple second risk values ​​using a first set of fusion coefficients to obtain multiple initial fusion values; and fusing the multiple initial fusion values ​​with multiple second risk values ​​using a second set of fusion coefficients to obtain multiple updated trust values.

[0098] In this embodiment, the first set of fusion coefficients can be coefficients configured in the access control device, coefficients transmitted to the access control device from other devices, or coefficients obtained by the access control device in other ways. The specific way in which the access control device obtains the first set of fusion coefficients can be determined according to the actual situation, and this embodiment does not limit it.

[0099] In this embodiment of the application, the process of fusing the current trust value with multiple second risk values ​​using a first set of fusion coefficients to obtain multiple initial fusion values ​​includes: determining the product between the first fusion value in the first set of fusion coefficients and the current trust value to obtain a first fusion value; determining the product between the second fusion value in the first set of fusion coefficients and multiple second risk values ​​to obtain multiple second fusion values; and determining the sum of the first fusion value and the multiple second fusion values ​​to obtain multiple initial fusion values.

[0100] In this embodiment, the weight of the historical data trust value is μ1, and the weight of the real-time data trust value is μ2 (i.e., the first set of fusion coefficients μ1 and μ2), where μ1∈[0,1], μ2∈[0,1], and μ1+μ2=1. Then, according to T... 用户行为 =μ1T 历史 +μ2T 实时 The fusion formula combines the first set of fusion coefficients (μ1 and μ2) and the current trust value (T). 实时 ) respectively and the second risk value (T 历史 The initial fusion value (T) is obtained by fusion. 用户行为 ), where T∈[0,1].

[0101] In this embodiment, the second set of fusion coefficients can be coefficients configured in the access control device, coefficients transmitted to the access control device from other devices, or coefficients obtained by the access control device in other ways. The specific way in which the access control device obtains the second set of fusion coefficients can be determined according to the actual situation, and this embodiment does not limit this.

[0102] In this embodiment of the application, the process of fusing multiple initial fusion values ​​with multiple second risk values ​​using a second set of fusion coefficients to obtain multiple updated trust values ​​includes: determining the product between the first coefficient in the second set of fusion coefficients and the multiple initial fusion values ​​to obtain multiple third products; determining the product between the second coefficient in the second set of fusion coefficients and the multiple second risk values ​​to obtain multiple fourth products; and determining the sum between the multiple third products and the multiple fourth products to obtain multiple updated trust values.

[0103] It should be noted that the multiple updated trust values ​​correspond one-to-one with the multi-level labels, that is, one level label corresponds to one updated trust value.

[0104] In this embodiment, the user's overall trust value T can be calculated by combining the identity authentication result and the behavior audit result (including historical and real-time results). That is, the trust value weight of the communication network is set to α. i The user behavior trust value weight is β. i (Second group fusion coefficient α) i and β i ), where α i ∈[0,1], β i ∈[0,1],α i +β i =1; using T=α i T 通信网络 +β i T 用户行为 Formula, the second set of fusion coefficients (α) i and β i ), initial fusion value (T) 用户行为 ) and second risk value (T) 通信网络 The values ​​are merged to obtain multiple updated trust values, where i∈S and T∈[0,1].

[0105] It should be noted that the access control device, by combining the tag results corresponding to the user's access to the system, empowers the business system (business server) so that the business system can determine the user's trustworthiness and assign corresponding access permissions.

[0106] In this embodiment, the access control device updates multiple initial trust values ​​corresponding to multi-level tags using the current trust value. After obtaining multiple updated trust values, if the current trust value is less than a preset trust threshold, it transmits multiple updated trust values ​​to the business server and prohibits the transmission of business access requests to the business server.

[0107] In this embodiment, the preset trust value can be a trust value configured in the access control device; it can also be a trust value transmitted to the access control device from other devices; or it can be a trust value obtained by the access control device in other ways. The specific way in which the access control device obtains the preset trust value can be determined according to the actual situation, and this embodiment does not limit it.

[0108] It should be noted that if the current trust value is less than the preset trust threshold, it indicates that the service access request is an illegal access request or an access request with malicious traffic risk. The access control device will directly block the service access request and will no longer transmit the service access request to the service server.

[0109] In this embodiment, if the access control device determines that the current trust value is less than a preset trust threshold, it may transmit multiple updated trust values ​​to the business server; alternatively, it may not transmit multiple updated trust values ​​to the business server. The specific method can be determined based on the actual situation, and this embodiment does not limit this.

[0110] S103. Transmit multiple updated trust values ​​and business access requests to the business server so that the business server can determine the execution process of the business access requests based on the multiple updated trust values.

[0111] In this embodiment, the access control device updates multiple initial trust values ​​corresponding to multi-level labels using the current trust value. After obtaining multiple updated trust values, it transmits multiple updated trust values ​​and a business access request to the business server so that the business server can determine the execution process of the business access request based on the multiple updated trust values.

[0112] In this embodiment of the application, the process of the access control device transmitting multiple updated trust values ​​and business access requests to the business server includes: transmitting multiple updated trust values ​​and business access requests to the business server when the current trust value is greater than or equal to a preset trust threshold.

[0113] In this embodiment of the application, if the current trust value is greater than or equal to the preset trust threshold, it indicates that the service access request is a legitimate access request or an access request that does not pose a risk of malicious traffic. In this case, the access control device does not need to block the service access request, but instead transmits multiple updated trust values ​​and service access requests to the service server.

[0114] In this application embodiment, an exemplary access control device (“Meta-Trust Security” center) is as follows: Figure 2 As shown, it includes three modules: a full-dimensional, full-volume behavior auditing module, a tag classification and grading module, and a carrier network control module. Using the carrier network as a medium, a "meta-trust security" center is established between the user (client) and the business system (business server). Identity verification is achieved using the carrier's unique SIM card authentication. After user access is granted, a user trust value is calculated in conjunction with user behavior auditing, and the trust value is dynamically adjusted and tags are dynamically assigned. Combined with security monitoring and defense equipment, an end-to-end path is opened at the carrier network level, providing dual protection against attacks from both the network and application levels, achieving trusted access and network security protection.

[0115] In this embodiment of the application, the process from a user initiating an access request to the operation of the business system can be summarized as follows: Figure 3 The timing diagram shown mainly includes steps (1)-(16).

[0116] (1) The user (client) initiates an access request to the business system (business server) to the "Meta-Trust Security" center, and the user's identity is authenticated by the operator's unique mobile phone number and SIM card information.

[0117] (2) The “Meta-Trust Security” center forwards the authenticated user ID card information to the business system.

[0118] (3) The business system performs identity authentication based on the user's ID card information.

[0119] (4) The business system sends its own business attributes to the label classification and grading module of the "Meta-Trust Security" center.

[0120] (5) The tag classification and grading module matches the received business attributes with its own tag library to obtain the corresponding industry and domain tags of the business system and sends them to the full-dimensional and full-volume behavior audit module.

[0121] (6) The full-dimensional and full-volume behavior audit module retrieves and audits the user's historical identity and behavior under this industry and field tag.

[0122] (7) The full-dimensional and full-volume behavior audit module calculates the trust value of this user under three levels of tags and sends the results to the business system.

[0123] (8) The business system determines the trust value of the three levels of tags obtained based on its own security requirements.

[0124] (9) The business system sends the trusted user's business access permission to the operator's network control module, along with the permissions assigned to this user.

[0125] (10) After receiving the permission, the operator's network control module will authorize the user with the permissions allocated by the business system and open the end-to-end access path.

[0126] (11) Users access the customized network access service system provided by the operator's network control module.

[0127] (12) User dynamic behavior information such as network access in the business system will be sent to the full-dimensional full-volume behavior audit module.

[0128] (13) The full-dimensional and full-volume behavior audit module performs audit analysis based on the user's real-time access behavior and adjusts the user's trust value based on whether the access behavior is legal.

[0129] (14) The full-dimensional and full-volume behavior audit module sends the adjusted trust values ​​of the three levels to the business system.

[0130] (15) The operator’s network control module blocks illegal behavior based on real-time access behavior and forwards legitimate behavior requests to the business system.

[0131] (16) The business system accesses the “Meta-Trust Security” center API interface to obtain the latest trust value of the user according to its own security policy, and dynamically adjusts the user’s permissions based on the trust value.

[0132] During this process, only users who pass identity authentication and whose tag trust value meets the requirements will be assigned and granted permissions, and will access the business system through the operator network provided by the "Meta-Trust Security" center. After accessing the business system, the user's behavior will be audited in real time, and if a network attack occurs, the protection module of the "Meta-Trust Security" center will block it. Both attack behaviors and non-attack behaviors that violate the business system's operating procedures will have their trust value under the user's current tag lowered in real time by the trust module of the "Meta-Trust Security" center.

[0133] The system provides open API interfaces, allowing business systems to obtain the latest user trust values ​​by calling the API through business identifiers and user identifiers based on their own security policies. Business systems can then dynamically adjust and restrict user permissions. The trust values ​​corresponding to the three-level tags are shared and made public by the operator's network. Through professional security analysis, all business platforms in the same domain under the current tag are empowered, thereby achieving inter-business collaboration.

[0134] It should be noted that this is an exemplary access control method flow. Figure 4 As shown:

[0135] S1. Upon receiving a login request from the client's login service server, obtain the login object information of the login object.

[0136] S2. If the login object information is verified, the login object information is transmitted to the business server so that the business server can perform object identity authentication based on the login object information.

[0137] S3. Upon receiving feedback information from the business server indicating successful object authentication, obtain the corresponding business attribute information from the business server.

[0138] S4. Determine multiple initial trust values ​​for the login object information based on business attribute information; and transmit multiple initial trust values ​​to the business server so that the business server can determine the client's trustworthiness based on the multiple initial trust values.

[0139] S5. Upon receiving an indication from the business server that the client is a trusted client, establish a target access path from the client to the business server.

[0140] S6. On the target access path between the client and the business server, when a business access request is received from the client, determine the current trust value based on the access traffic corresponding to the business access request.

[0141] S7. Obtain the historical access information corresponding to the logged-in object, and obtain multiple first historical access traffic corresponding to multi-level tags within the first preset historical time period and multiple first historical access logs corresponding to multi-level tags within the second preset historical time period from the historical access information.

[0142] It should be noted that multiple first historical access traffic refers to network traffic that is at risk; multiple first historical access logs refer to all access logs within the second preset time period; and the login object refers to the object that transmits business access requests through the client.

[0143] S8. From multiple first historical access traffic, obtain multiple first access traffic traced back based on the login object and multiple second access traffic traced back based on the client's address information.

[0144] It should be noted that the multiple second access traffic refers to the access traffic other than the multiple first access traffic among the multiple first historical access traffic.

[0145] S9. Based on multiple first access traffic volumes and multiple first attenuation coefficients, determine multiple third risk values; based on multiple second access traffic volumes and multiple first attenuation coefficients, determine multiple fourth risk values.

[0146] S10. Merge multiple third-risk values ​​and multiple fourth-risk values ​​to obtain multiple first-risk values.

[0147] S11. Obtain access logs without access risks from each of the multiple first historical access logs to obtain multiple first access logs; determine multiple second risk values ​​based on the multiple first access logs, the multiple first historical access logs, and the first attenuation coefficient.

[0148] S12. Using the first set of fusion coefficients, the current trust value is fused with multiple second risk values ​​to obtain multiple initial fusion values; using the second set of fusion coefficients, the multiple initial fusion values ​​are fused with multiple second risk values ​​to obtain multiple updated trust values.

[0149] S13. If the current trust value is greater than or equal to the preset trust threshold, transmit multiple updated trust values ​​and business access requests to the business server so that the business server can determine the execution process of the business access request based on the multiple updated trust values.

[0150] Understandably, the access control device determines the current trust value based on the access traffic corresponding to the business access request, uses the current trust value to adjust multiple initial trust values ​​to obtain multiple updated trust values, and sends these multiple updated trust values ​​and the business access request to the business server. This allows the business server to determine whether to execute the access process corresponding to the business access request based on the multiple updated trust values, thereby improving the security of network access.

[0151] Based on the same inventive concept as the above-described access control method, this application provides an access control device 1, corresponding to an access control method; Figure 5 A schematic diagram of the composition structure of an access control device provided in this application embodiment. Figure 1 The access control device 1 may include:

[0152] The determining unit 11 is used to determine the current trust value based on the access traffic corresponding to the service access request when a service access request transmitted by the client is received on the target access path between the client and the service server.

[0153] Update unit 12 is used to update multiple initial trust values ​​corresponding to multi-level tags using the current trust value, so as to obtain multiple updated trust values;

[0154] The transmission unit 13 is used to transmit the plurality of updated trust values ​​and the service access request to the service server, so that the service server can determine the execution process of the service access request based on the plurality of updated trust values.

[0155] In some embodiments of this application, the apparatus further includes a fusion unit and an acquisition unit;

[0156] The acquisition unit is used to acquire historical access information corresponding to the login object, and to acquire multiple first historical access traffic flows corresponding to the multi-level tags within a first preset historical time period and multiple first historical access logs corresponding to the multi-level tags within a second preset historical time period from the historical access information; the multiple first historical access traffic flows are network traffic that accesses at risk; the multiple first historical access logs are all access logs within the second preset time period; the login object is the object that transmits the service access request through the client;

[0157] The determining unit 11 is configured to determine multiple first risk values ​​based on the multiple first historical access traffic; and to determine multiple second risk values ​​based on the multiple first historical access logs.

[0158] The fusion unit is used to fuse the current trust value, the plurality of first risk values ​​and the plurality of second risk values ​​to obtain the plurality of updated trust values.

[0159] In some embodiments of this application, the acquisition unit is configured to acquire, respectively, multiple first access traffic traced back based on the login object and multiple second access traffic traced back based on the client's address information from the multiple first historical access traffic; the multiple second access traffic are access traffic other than the multiple first access traffic in the multiple first historical access traffic.

[0160] The determining unit 11 is configured to determine a plurality of third risk values ​​based on the plurality of first access traffic and the plurality of first attenuation coefficients; and to determine a plurality of fourth risk values ​​based on the plurality of second access traffic and the plurality of first attenuation coefficients.

[0161] The fusion unit is used to fuse the plurality of third risk values ​​and the plurality of fourth risk values ​​to obtain the plurality of first risk values.

[0162] In some embodiments of this application, the acquisition unit is used to acquire access logs that do not pose an access risk from each of the plurality of first historical access logs, thereby obtaining a plurality of first access logs;

[0163] The determining unit 11 is used to determine multiple second risk values ​​based on the multiple first access logs, the multiple first historical access logs, and the first attenuation coefficient.

[0164] In some embodiments of this application, the fusion unit is configured to use a first set of fusion coefficients to fuse the current trust value with the plurality of second risk values ​​respectively to obtain a plurality of initial fusion values; and use a second set of fusion coefficients to fuse the plurality of initial fusion values ​​with the plurality of second risk values ​​to obtain the plurality of updated trust values.

[0165] In some embodiments of this application, the determining unit 11 is used to take a first preset value as the current trust value when the access traffic is traffic without access risk; and to take a second preset value as the current trust value when the access traffic is traffic with access risk.

[0166] In some embodiments of this application, the transmission unit 13 is used to transmit the plurality of updated trust values ​​to the service server when the current trust value is less than a preset trust threshold, and to prohibit the transmission of the service access request to the service server.

[0167] In some embodiments of this application, the transmission unit 13 is used to transmit the plurality of updated trust values ​​and the service access request to the service server when the current trust value is greater than or equal to a preset trust threshold.

[0168] In some embodiments of this application, the apparatus further includes an establishment unit;

[0169] The acquisition unit is used to acquire login object information of the login object when it receives a login request to log in to the business server transmitted by the client; and to acquire business attribute information corresponding to the business server when it receives feedback information that the object's identity authentication is successful transmitted by the business server.

[0170] The transmission unit 13 is used to transmit the login object information to the business server when the login object information is verified to be valid, so that the business server can perform object identity authentication based on the login object information; and to transmit the plurality of initial trust values ​​to the business server so that the business server can determine the trustworthiness of the client based on the plurality of initial trust values.

[0171] The determining unit 11 is used to determine multiple initial trust values ​​of the login object information based on the business attribute information;

[0172] The establishment unit is used to establish a target access path from the client to the business server when it receives indication information from the business server that the client is a trusted client.

[0173] In some embodiments of this application, the acquisition unit is used to acquire the client permission information of the client from the indication information;

[0174] The transmission unit 13 is used to transmit the target access path and the client permission information to the client, so that the client can execute the access process of the service access request according to the client permission information and the target access path.

[0175] In some embodiments of this application, the determining unit 11 is used to determine industry tags and domain tags that match the business attribute information; determine the comprehensive tag corresponding to the login object information; and treat the industry tags, domain tags, and comprehensive tags as multi-level tags;

[0176] The fusion unit is used to fuse multiple first risk values ​​and multiple second risk values ​​to obtain the multiple initial trust values ​​corresponding to the multi-level labels.

[0177] It should be noted that, in practical applications, the aforementioned determining unit 11, updating unit 12, and transmission unit 13 can be implemented by the processor 14 on the access control device 1, specifically by a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processor), or Field Programmable Gate Array (FPGA); the aforementioned data storage can be implemented by the memory 15 on the access control device 1.

[0178] This application embodiment also provides an access control device 1, such as... Figure 6 As shown, the access control device 1 includes a processor 14, a memory 15, and a communication bus 16. The memory 15 communicates with the processor 14 through the communication bus 16. The memory 15 stores programs executable by the processor 14. When the program is executed, the access control method described above is executed by the processor 14.

[0179] In practical applications, the aforementioned memory 15 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the processor 14.

[0180] This application provides a computer-readable storage medium having a computer program thereon, which, when executed by a processor 14, implements the access control method as described above.

[0181] Understandably, the access control device determines the current trust value based on the access traffic corresponding to the service access request, uses the current trust value to adjust multiple initial trust values ​​to obtain multiple updated trust values, and sends these multiple updated trust values ​​and the service access request to the service server. This allows the service server to determine whether to execute the access process corresponding to the service access request based on the multiple updated trust values, thereby improving the security of network access.

[0182] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0183] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0184] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0185] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0186] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. An access control method, characterized in that, The method includes: When a business access request is received from the client on the target access path between the client and the business server, the current trust value is determined based on the access traffic corresponding to the business access request. The current trust value is used to update multiple initial trust values ​​corresponding to multi-level tags, resulting in multiple updated trust values. The updated trust values ​​and the service access request are transmitted to the service server so that the service server can determine the execution process of the service access request based on the updated trust values. The step of updating multiple initial trust values ​​corresponding to multi-level tags using the current trust value to obtain multiple updated trust values ​​includes: Obtain historical access information corresponding to the login object, and obtain multiple first historical access traffic flows corresponding to the multi-level tags within a first preset historical time period and multiple first historical access logs corresponding to the multi-level tags within a second preset historical time period from the historical access information; the multiple first historical access traffic flows are network traffic that accesses at risk; the multiple first historical access logs are all access logs within the second preset time period; the login object is the object that transmits the business access request through the client; Based on the aforementioned multiple first historical access traffic, multiple first risk values ​​are determined; Based on the aforementioned multiple first historical access logs, multiple second risk values ​​are determined; The current trust value, the plurality of first risk values, and the plurality of second risk values ​​are merged to obtain the plurality of updated trust values.

2. The method according to claim 1, characterized in that, The determination of multiple first risk values ​​based on the multiple first historical access traffic includes: From the plurality of first historical access traffic, obtain the plurality of first access traffic traced back to the login object and the plurality of second access traffic traced back to the client's address information; the plurality of second access traffic are the access traffic other than the plurality of first access traffic in the plurality of first historical access traffic; Based on the multiple first access traffic volumes and multiple first attenuation coefficients, multiple third risk values ​​are determined; Based on the plurality of second access traffic and the plurality of first attenuation coefficients, a plurality of fourth risk values ​​are determined; The plurality of third risk values ​​and the plurality of fourth risk values ​​are merged to obtain the plurality of first risk values.

3. The method according to claim 1, characterized in that, The determination of multiple second risk values ​​based on the multiple first historical access logs includes: From each of the plurality of first historical access logs, obtain access logs that do not pose an access risk, thus obtaining a plurality of first access logs; Based on the plurality of first access logs, the plurality of first historical access logs, and the first attenuation coefficient, a plurality of second risk values ​​are determined.

4. The method according to claim 1, characterized in that, The step of fusing the current trust value, the plurality of first risk values, and the plurality of second risk values ​​to obtain the plurality of updated trust values ​​includes: The current trust value is fused with the plurality of second risk values ​​using the first set of fusion coefficients to obtain a plurality of initial fusion values; The multiple initial fusion values ​​are fused with the multiple second risk values ​​using the second set of fusion coefficients to obtain the multiple updated trust values.

5. The method according to claim 1, characterized in that, The step of determining the current trust value based on the access traffic corresponding to the service access request includes: If the access traffic is not at risk, the first preset value will be used as the current trust value. If the access traffic is considered to be at risk, the second preset value will be used as the current trust value.

6. The method according to claim 1, characterized in that, After updating multiple initial trust values ​​corresponding to multi-level tags using the current trust value to obtain multiple updated trust values, the method further includes: If the current trust value is less than a preset trust threshold, the updated trust values ​​are transmitted to the business server, and the transmission of the business access request to the business server is prohibited.

7. The method according to claim 1, characterized in that, The transmission of the multiple updated trust values ​​and the service access request to the service server includes: If the current trust value is greater than or equal to a preset trust threshold, the updated trust values ​​and the service access request are transmitted to the service server.

8. The method according to claim 1, characterized in that, Before determining the current trust value based on the access traffic corresponding to the service access request when a service access request is received from the client on the target access path between the client and the service server, the method further includes: Upon receiving a login request from the client to log in to the business server, obtain the login object information of the login object; If the login object information is verified, the login object information is transmitted to the business server so that the business server can perform object identity authentication based on the login object information; Upon receiving feedback information from the business server indicating successful object authentication, the business attribute information corresponding to the business server is obtained. Based on the business attribute information, multiple initial trust values ​​are determined for the login object information; and the multiple initial trust values ​​are transmitted to the business server so that the business server can determine the trustworthiness of the client based on the multiple initial trust values. Upon receiving indication from the business server that the client is a trusted client, a target access path is established from the client to the business server.

9. The method according to claim 8, characterized in that, The step of establishing a target access path from the client to the business server upon receiving indication information from the business server that the client is a trusted client further includes: Obtain the client's permission information from the instruction information; The target access path and the client permission information are transmitted to the client so that the client can execute the access process of the service access request based on the client permission information and the target access path.

10. The method according to claim 8, characterized in that, The process of determining multiple initial trust values ​​for login object information based on the business attribute information includes: Determine the industry tags and domain tags that match the business attribute information; Determine the comprehensive tag corresponding to the login object information; and use the industry tag, domain tag, and comprehensive tag as multi-level tags; Obtain historical access information corresponding to the login object information according to the multi-level tags; The plurality of initial trust values ​​are determined based on the historical access information.

11. An access control device, characterized in that, The device includes: The determining unit is used to determine the current trust value based on the access traffic corresponding to the service access request when a service access request transmitted by the client is received on the target access path between the client and the service server. The update unit is used to update multiple initial trust values ​​corresponding to multi-level tags using the current trust value, so as to obtain multiple updated trust values; A transmission unit is used to transmit the multiple updated trust values ​​and the service access request to the service server, so that the service server can determine the execution process of the service access request based on the multiple updated trust values. The device further includes a fusion unit and an acquisition unit; The acquisition unit is used to acquire historical access information corresponding to the login object, and to acquire multiple first historical access traffic flows corresponding to the multi-level tags within a first preset historical time period and multiple first historical access logs corresponding to the multi-level tags within a second preset historical time period from the historical access information; the multiple first historical access traffic flows are network traffic that accesses at risk; the multiple first historical access logs are all access logs within the second preset time period; the login object is the object that transmits the service access request through the client; The determining unit is configured to determine multiple first risk values ​​based on the multiple first historical access traffic; and to determine multiple second risk values ​​based on the multiple first historical access logs. The fusion unit is used to fuse the current trust value, the plurality of first risk values ​​and the plurality of second risk values ​​to obtain the plurality of updated trust values.

12. An access control device, characterized in that, The device includes: The system includes a memory, a processor, and a communication bus, wherein the memory communicates with the processor via the communication bus, and the memory stores an access control program executable by the processor, wherein when the access control program is executed, the method described in any one of claims 1 to 10 is performed by the processor.

13. A storage medium having a computer program stored thereon for use in an access control device, characterized in that, When executed by a processor, the computer program implements the method described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Dynamic access control method based on trust value and control system thereof

    CN115587374A